GetUpp

Denmark · owned by Milestone Invest ApS (Denmark) · getupp.com · 16 vendors

GetUpp helps organizations improve employee health, engagement, and productivity through science-backed wellbeing programs. The company operates a workplace wellbeing platform targeting businesses seeking to enhance workforce wellness. Its website is served in Danish, indicating a primary base of operations in Denmark.

Resilience scores

Technology vendors

Insights

Last updated 2026-09-13 · revision 7

16 direct vendors, 217 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 4/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

GetUpp's migration readiness is assessed as medium, scoring 35 out of 100, primarily due to significant unknowns and regulatory constraints. A major challenge is the complete lack of information regarding GetUpp's internal tech stack (e.g., cloud-native architecture, containerization, microservices). This absence of data makes it impossible to accurately assess the technical complexity, effort, and potential cost required for any migration. As a Danish company, GetUpp is subject to strict GDPR and EU data residency requirements. These regulations significantly constrain the choice of cloud providers and data center locations for any migration, necessitating careful planning for data transfers and compliance. The 'Vendor Lock-in Risk' is unknown, and with 52 identified services, there is a potential for complex integrations and dependencies with existing vendors that could complicate disentanglement during a migration. Additionally, there is no data available on GetUpp's financial stability, making it difficult to assess the company's ability to fund a potentially costly and resource-intensive migration project. No specific opportunities for migration readiness are evident from the provided data.

Compliance

5 in-scope frameworks identified; showing 3.

SOC 2 (source) — Assessment Required

SOC2 is voluntary but increasingly expected for SaaS/cloud service providers, especially those serving enterprise clients. As an HR technology company likely offering cloud-based services, clients may require SOC2 Type II reports for vendor due diligence. Medium risk as lack of SOC2 could limit enterprise sales opportunities and client trust, though not legally mandatory.

Danish Data Protection Act — Assessment Required

As a Danish company, GetUpp must comply with national implementation of GDPR through the Danish Data Protection Act. This includes additional national provisions beyond GDPR requirements. High risk due to local enforcement by Datatilsynet and potential for specific Danish requirements regarding employee data processing and workplace monitoring.

EU AI Act (source) — Assessment Required

If GetUpp uses AI/ML in their wellbeing platform (e.g., for analytics, recommendations, performance assessment), EU AI Act may apply. HR applications involving AI for recruitment, performance evaluation, or employee monitoring are considered high-risk under the Act. Medium risk as compliance requirements are significant if AI is used, but may not apply if platform is purely data collection/reporting without AI components.

Financials

Three-year financials

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report